CSIDB logo
Incident

pcTattletale

Incident posture

Attack window
2024
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 12:08

Linked entities

Victim
pcTattletale
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

pcTattletale, a US-based consumer spyware application, suffered a major breach when an unknown hacker broke into its servers, stole internal data, and defaced its public website in a shaming operation. The compromise exposed the personal information of over 138,000 customers and had previously revealed real-time screenshots from victims' devices on a publicly accessible site. The breach, combined with prior reporting that the software had been used to monitor hotel check-in computers, led founder Bryan Fleming to shut down the operation. Separately, Fleming faced federal prosecution in San Diego, where he pleaded guilty to computer hacking, conspiracy, and selling and advertising surveillance software for unlawful purposes, becoming the first US spyware operator convicted in over a decade.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

pcTattletale was a US-based consumer spyware application marketed to individuals who wanted to monitor smartphones and personal computers. Once secretly installed on a victim's device, the app continuously uploaded copies of messages, photos, location data, and other information to a pcTattletale server, allowing the operator to eavesdrop on the target. The product was commonly categorized as stalkerware because it was frequently promoted to jealous partners and spouses as a way to catch cheating loved ones. pcTattletale was operated from the home of its founder, Brian Fleming, in Michigan, placing the company within the jurisdiction of US law enforcement. Fleming is alleged to have been selling the spyware from at least 2017 through 2022, advertising the software through affiliate marketers and promotional materials that emphasized its use for covert surveillance of intimate partners.

The formal investigation into pcTattletale began in June 2021, when authorities identified more than 100 websites offering spyware, many of which presented the software as a legitimate tool for monitoring children or employees. In November 2021, Homeland Security Investigations Special Agent Nick Jones made contact with Fleming by posing as an affiliate marketer. Fleming sent Jones a promotional banner image for pcTattletale that carried the caption "The #1 Spy App for Catching Cheating Partners." Fleming later allegedly offered to assist Jones in installing the app on the smartphone of Jones's boyfriend, an action that helped establish intent to facilitate unlawful surveillance. These interactions contributed to the issuance of a search warrant, which led law enforcement to search Fleming's home and seize his bank and PayPal accounts. Fleming's attorney, Marcus Bourassa, later stated that Fleming had no idea the products might violate the law, and that as soon as he became aware of the issue he stopped operations and cooperated with investigators.

In May 2024, a separate incident brought pcTattletale into public view when researchers and journalists reported that the spyware had been found installed on front desk check-in computers at a US hotel chain, where it was capturing screenshots of guest information and transmitting them to a publicly accessible website. This exposure revealed that pcTattletale had been configured to stream victim device screenshots in real time to a web destination that anyone could access, compounding the privacy impact of the underlying surveillance. The visibility of that report preceded a direct attack on the company itself. In 2024, an unknown hacker broke into pcTattletale's servers, stole internal company data, leaked that data online, and defaced the company's official website. The attacker referenced the recent reporting about the hotel check-in computers as motivation for the intrusion, framing the operation as an effort to embarrass the company. As a result of the breach, the leak, and the defacement, Fleming announced that he was shutting down pcTattletale. The breach ultimately led to the exposure of personal information belonging to more than 138,000 pcTattletale customers, and the company did not resume operations.

The criminal case against Fleming continued to develop in parallel with the breach. In January 2026, Fleming pleaded guilty in San Diego federal court to charges of computer hacking and the sale and advertising of surveillance software for unlawful purposes. The plea was reported as a rare prosecution, described as the first conviction in the United States for spyware operations in more than a decade, following the 2014 indictment and guilty plea of the developer behind the cell phone monitoring app StealthGenie. Fleming's sentencing was scheduled for later in 2026. The case was built on evidence gathered from the 2021 undercover contact, the subsequent search of Fleming's home, and the seizure of financial accounts that documented the sale of the software over several years. Reporting on the plea noted that Fleming's onshore US base of operations was a critical factor enabling investigators to pursue the case, in contrast to many spyware operators who operate from outside the United States.

The pcTattletale incident occurred within a broader pattern of stalkerware and consumer spyware compromises documented over the preceding years. According to industry tallies, pcTattletale was among at least 27 stalkerware companies known to have been hacked or to have leaked customer and victim data since 2017, and it appeared on chronological lists of such incidents with recorded exposure events in both 2021 and 2024. Prior to its 2024 breach, pcTattletale had also experienced a data exposure in which screenshots of victim devices were uploaded in real time to a website that anyone could access, an issue that predated the more widely reported 2024 intrusion. The 2024 breach and the subsequent guilty plea together ended the company's operations and marked a notable US enforcement action against a domestic stalkerware operator, with court records, seized financial accounts, and a public plea establishing the documented timeline of the case.

Sources

Sources available to members: 2 sources.

CSIDB